Try our new research platform with insights from 80,000+ expert users

FortiWeb Web Application Firewall (WAF) vs Prisma Cloud by Palo Alto Networks comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
71
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
FortiWeb Web Application Fi...
Average Rating
8.2
Number of Reviews
22
Ranking in other categories
Web Application Firewall (WAF) (16th)
Prisma Cloud by Palo Alto N...
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
108
Ranking in other categories
Web Application Firewall (WAF) (5th), Container Security (1st), Cloud Workload Protection Platforms (CWPP) (1st), Cloud Security Posture Management (CSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (1st), Data Security Posture Management (DSPM) (1st)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Nitith Unarat - PeerSpot reviewer
Identifies potential DDoS attacks and suspicious domain activity
The price could be close to Imperva; Imperva is the number one firewall. FortiWeb cannot do some kind of ADC solution, like load balancing. I hope they improve that. I'm looking for the ADC solution, the load balancing solution. Because application firewalls with multiple line solutions do come with it. So, I think it should be integrated within FortiWeb WAF.
Mohammad Qaw - PeerSpot reviewer
It gives you one console to see all of your assets, review their configurations, and build your processes
Most customers use Prisma Cloud for visibility and compliance. Prisma has so many features, but many organizations do not use them. They primarily use the visibility part to connect all their cloud accounts and hosts for visibility to see if they are missing any security controls or if they have any misconfigurations. You can connect it to cloud environments such as Azure, AWS, Oracle Cloud, Alibaba, etc., or to an on-prem data center. Prisma Cloud gives you so many options to automate processes related to your daily operations. When it comes to cybersecurity, you can automate things with their existing APIs. They also have out-of-the-box integrations with many solutions. I have not seen any limitations. Everything is customizable. You can do whatever you want, defining the reporting and custom use cases. They recently updated the UI, so it's much better than before.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Easier http to https redirect using page rules"
"There are key things that are used for our enterprise customers, such as Lambda and DNS."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"It is easier to configure and develop documentation to see how we have configured firewalls."
"What I like best about Cloudflare is that my company can use it to trace and manage applications and monitor traffic. The solution tells you if there's a spike in traffic. Cloudflare also sends you a link to check your equipment and deployment and track it through peering, so it's a valuable tool."
"The most valuable feature of Cloudflare is the GUI. You are able to control the solution very well through the interface. There is a lot of functionality that is embedded in the service."
"The UI is good."
"It is a stable solution. I rate the stability a ten out of ten...I rate the scalability a ten out of ten."
"FortiWeb identified potential DDoS attacks and suspicious domain activity, showcasing the value of its machine-learning capabilities."
"The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS."
"The product is easy to configure."
"FortiWeb Web Application Firewall blocks attacks from application layers and provides protection."
"It improves latency by optimizing traffic routing."
"The machine learning feature reduces the false positives."
"The platform's stability is good."
"The most valuable feature is the tool's integration with load-balancing applications, similar to FortiADC. Its importance depends on customer requirements, such as whether they prioritize application load balancing or layer seven protection."
"The CVEs are valuable because we used to have a tool to scan CVEs, at the language level, for the dependencies that our developers had. What is good about Prisma Cloud is that the CVEs are not only from the software layer, but from all layers: the language, the base image, and you also have CVEs from the host. It covers the full base of security."
"I like Prisma's ability to integrate with other tools. We can integrate it with Jira so that when Prisma triggers an alert, it opens a ticket in Jira. That was a big selling point for the product. There's a feature called the guest custom template that allows you to trigger alerts in Jira based on the template. That can also be added as a feature on Jira."
"In the GlobalProtect module, we can easily guide users experiencing connection issues through the notification column."
"We found it to be easy and flexible. We could easily configure it for our needs, and we could spread the Prisma Cloud platform to 16 countries without encountering any kind of problem."
"Configuration monitoring and alerting is the most valuable feature; it happens at the cloud's speed, allowing our development team to respond quickly. If a configuration goes against our security best practices, we're alerted promptly and can act to resolve the issue. As cloud security staff, we're not staring at the cloud all the time, and we want to let the developers do their jobs so that our company is protected and work is proceeding within our security controls."
"The runtime mechanism on the solution is very useful. It's got very good network mapping between containers. If you have more than one container, you can create a content data link between them."
"It scans our containers in real time. Also, as they're built, it's looking into the container repository where the images are built, telling us ahead of time, "You have vulnerabilities here, and you should update this code before you deploy." And once it's deployed, it's scanning for vulnerabilities that are in production as the container is running."
"The solution will streamline and minimize manual efforts."
 

Cons

"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"The documentation could improve for Cloudflare DNS."
"DNS Management."
"Cloudflare does not have an on-premise solution. If they had different approaches they could be better suited to accommodate more customers, such as on-premise and hybrid deployments. For example, hybrid deployments would be useful where you could move the traffic from the enterprise to the cloud."
"Latencies are always a problem."
"Cloudflare should add more documentation and pricing to the cloud version."
"In the last two years, there has been a certain amount of downtime when using the VDM."
"The pricing could be improved."
"We haven't faced any significant issues with FortiWeb Web Application Firewall. But they can lower the pricing, since it is a concern, especially in South Africa and the technical support, could be more responsive at times."
"There could be ADC offering as well."
"There is room for improvement in the support. The response time could be faster. Plus, they ask for a lot of information. It is not easy to get support."
"FortiWeb WAF's tuning causes trouble. It's complicated. The solution needs to improve the signature feature as well."
"The price is a little higher than the competitors."
"WAF needs more signatures on FortiWeb and updates the database continuously to protect against new attacks."
"The tool's price and performance are areas of concern where improvements are required."
"FortiWeb Web Application Firewall (WAF) needs to update its attack prevention database."
"When there are updates, whether daily, weekly, or monthly, it needs configuration or permission adjustments. There is no automation for that, which is too bad."
"It's not really on par with, or catering to, what other products are looking at in terms of SAST and DAST capabilities. For those, you'd probably go to the market and look at something like Veracode or WhiteHat."
"It would be ideal if they could somehow reduce the deployment time."
"Prisma Cloud supports generating CSV files, but I would also like it to generate PDF files for reporting."
"The Palo Alto support needs to improve."
"Prisma Cloud's enterprise reporting needs significant improvement."
"The area for improvement is less about the product and more about the upsell. If we've already agreed that we'd like your product x, y, or z, don't try to add fries to my burger. I don't need it."
"I don't have any specific notes for improvement; however, if they could continue to focus more on giving users the ability to create custom policies and configurations, that would be ideal."
 

Pricing and Cost Advice

"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"The price is reasonable."
"The tool is a premium product, so it is very expensive."
"That is one of the great features. I was able to access the majority of the features and services for free."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"The price of the solution is expensive."
"In terms of licensing costs, we don't pay for licensing for Cloudflare. We only establish communication, then for peering, Cloudflare takes care of the cross-connection in different data centers."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"It is a cost-effective product. If you need an extra module in the product, there will be an extra cost in addition to the licensing fee."
"FortiWeb Web Application Firewall is not expensive."
"This product offers two pricing options: a standard package and an advanced package."
"FortiWeb WAF is priced well for customers compared to other vendors' solutions."
"FortiWeb has a good presence because of its price."
"FortiWeb Web Application Firewall's pricing is suited for small or medium organizations."
"The product provides very good prices to customers. The price is set well and offers great value for money."
"It is a cheap solution."
"The price is high. In the future, when there are more competitors at the same level with different clouds, maybe the position will be different."
"I find the pricing to be expensive."
"Prisma Cloud is a value-back cloud-managed solution; cloud-native solutions are quite expensive."
"If a competitor came along and said, "We'll give you half the price," that doesn't necessarily mean that's the right answer, at all. We wouldn't necessarily entertain it that way. Does it do what we need it to do? Does it work with the things that we want it to work with? That is the important part for us. Pricing wasn't the big consideration it might be in some organizations. We spend millions on public cloud. In that context, it would not make sense to worry about the small price differences that you get between the products."
"One thing we're very pleased about is how the licensing model for Prisma is based on work resources. You buy a certain amount of work resources and then, as they enable new capabilities within Prisma, it just takes those work resource units and applies them to new features. This enables us to test and use the new features without having to go back and ask for and procure a whole new product, which could require going through weeks, and maybe months, of a procurement process."
"The pricing is reasonable."
"The licensing cost is a bit high on the compute side."
"Our licensing fees are $18,000 USD per year."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
823,795 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
13%
Comms Service Provider
7%
Financial Services Firm
7%
Financial Services Firm
14%
Comms Service Provider
11%
Manufacturing Company
11%
Computer Software Company
11%
Educational Organization
17%
Financial Services Firm
13%
Computer Software Company
12%
Manufacturing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about FortiWeb Web Application Firewall (WAF)?
The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS.
What is your experience regarding pricing and costs for FortiWeb Web Application Firewall (WAF)?
FortiWeb uses a subscription-based license, but there is also an option for a perpetual license. It's not the cheapes...
What needs improvement with FortiWeb Web Application Firewall (WAF)?
For users not familiar with Fortinet, it could be beneficial to provide more user-friendly analytics and reporting. T...
What is your primary use case for Prisma Cloud by Palo Alto Networks ?
Prisma Cloud helps support DevSecOps methodologies, making those responsibilities easier to manage.
What Cloud-Native Application Protection Platform do you recommend?
We like Prisma Cloud by Palo Alto Networks, since it offers us incredible visibility into our entire cloud system. We...
What do you think of Aqua Security vs Prisma Cloud?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valu...
 

Also Known As

Cloudflare DNS
No data available
Palo Alto Networks Prisma Cloud, Prisma Public Cloud, RedLock Cloud 360, RedLock, Twistlock, Aporeto
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Information Not Available
Amgen, Genpact, Western Asset, Zipongo, Proofpoint, NerdWallet, Axfood, 21st Century Fox, Veeva Systems, Reinsurance Group of America
Find out what your peers are saying about FortiWeb Web Application Firewall (WAF) vs. Prisma Cloud by Palo Alto Networks and other solutions. Updated: December 2024.
823,795 professionals have used our research since 2012.